MAL-2026-12117
Dashboard / Malicious Package / MAL-2026-12117
MAL-2026-12117
Summary: Malicious code in 1239i32049i (npm)
Details: Source: amazon-inspector (6c99f6d077df7b1209fb59dafa8641b14b3947d321379bc6ad22f2660d3d4c7b) Package declares a postinstall script that runs dist/index.js, the sole shipped file, which is heavily obfuscated with javascript-obfuscator (rotated string array, _0xNNNN identifiers, control-flow dispatch). At install time it reads process.env.P, issues an HTTPS GET to https://dropper-crm.vercel.app/api/payload/<P>, base64-decodes the response body, and executes it via new Function('require', decoded), granting the remote endpoint arbitrary code execution with require access on the installing machine. The package name is a numeric string with no documented functionality, no README, and no legitimate purpose beyond delivery of the remote payload.
Affected packages
Package
Name: 1239i32049i
Purl: pkg:npm/1239i32049i
Affected ranges
Type: N/A
Events:
